Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!

  New Posts New Posts RSS Feed - Haxored
  FAQ FAQ  Forum Search   Events   Register Register  Login Login

Haxored

 Post Reply Post Reply Page  <1234>
Author
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 13 July 2005 at 5:35am
This is NOT a vulnerability in Web Wiz Forums!!

I've just been through 30 to 40 random sites that this hacker has hit and they are all running Windows web servers, but only 1 was running Web Wiz Forums.

To prevent this hacker it's just a case of simple security measures and making sure that you do not have write permissions enabled on your site.

To run web wiz forums Access version you need to have write permissions on the directory containing the Access database. This directory should be outside of your web site in a place on the server not accessible through a web browser. For more on this see the documentation that comes with Web Wiz Forums.


Edited by -boRg- - 13 July 2005 at 5:37am
Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 13 July 2005 at 2:27pm
Anyway...

Quote
Hi Paul,

Your email has been forwarded on to me by our datacentre provider. We provide the web hosting for slowdown.co.uk the site uses host header on the IP address 83.245.15.61. The attack did not originate from this IP address. However the hacker did deface a number of sites on the server. We believe he used a brute force password cracker on about 10 websites.

Unfortunately there is not allot in the logs that is useful. However we shall be adding an IDS system to the server by the end of the week to prevent this from happening again.

Please don't hesitate to contact me with any further questions or problems.

Best Regards

Adam Heavens
Managing Director
Server Centre Limited
Email: adam.heavens@servercentre.net
Tel: 0870 7606745
DDI: 0115 9419191
Mobile: 0773 4218194


Quote
Paul,

Thanks for the heads up, we're investigating.

Regards,

Ed Butler
RapidSwitch Ltd
DDI: 020 7106 0731
Back to Top
nolan View Drop Down
Newbie
Newbie


Joined: 10 July 2005
Status: Offline
Points: 4
Post Options Post Options   Thanks (0) Thanks(0)   Quote nolan Quote  Post ReplyReply Direct Link To This Post Posted: 15 July 2005 at 10:25am
Firstly I would like to thanks you guys for looking into this, it's great to get such a response.

Originally posted by pmormr pmormr wrote:

he's only hacking Win2k3 machines... he probably wrote a script that takes advantage of unprotected shares or unpatched holes in the OS... but he's only targeting WWFs.


I was thinking maybe it's the opposite way around, by searching for wwf's on the web they would know that a Win2k3 server is likely to be in use, so then they attack it. ?

Thinking about it that does make sense as I noticed some of the other sites that had been hacked where using some sort of free asp script, so it's an easy way to find these servers.

Anyway thanks again guys!

Lee

Back to Top
WebWiz-Bruce View Drop Down
Admin Group
Admin Group
Avatar
Web Wiz Developer

Joined: 03 September 2001
Location: Bournemouth
Status: Offline
Points: 9844
Post Options Post Options   Thanks (0) Thanks(0)   Quote WebWiz-Bruce Quote  Post ReplyReply Direct Link To This Post Posted: 15 July 2005 at 11:19am
Or even simpler just look for web pages that have a .asp extension as Google shows these under the decription of the site in searches.

Defacing sites that are running on servers with 'write' permissions enabled on directories within the site is a very old hacking trick and there are plenty of hacking tools to do this that are readily available.

Most hackers don't even both with this type of amateurish stuff, but there are still plenty of 13 year old skript kiddies with to much time on their hands who will use these tools to over-write files on un-secured sites.

Expect more of this type of thing with the summer holidays comming up.
Back to Top
pmormr View Drop Down
Senior Member
Senior Member


Joined: 06 January 2003
Location: United States
Status: Offline
Points: 1479
Post Options Post Options   Thanks (0) Thanks(0)   Quote pmormr Quote  Post ReplyReply Direct Link To This Post Posted: 15 July 2005 at 3:17pm
it's incredibly easy to hack unprotected directories if you don't know how to secure your server... it becomes even easier if it isn't behind some type of router or firewall

considering myself a pretty good windows security person... i would lockdown your server until you disable all write permissions on everything but the absolutely necessary... and then move your database out of the root directory of your website... that way... he can't get to it without actually hacking your server
Back to Top
ToJaRo View Drop Down
Groupie
Groupie
Avatar

Joined: 20 April 2005
Location: United States
Status: Offline
Points: 158
Post Options Post Options   Thanks (0) Thanks(0)   Quote ToJaRo Quote  Post ReplyReply Direct Link To This Post Posted: 06 August 2005 at 10:26am
Hello All,
I realize this topic is a few days old but thought I would throw in my 2 cents since i am just now catching up.   Windows 2003 SP1 comes with a tool called the Security Configuration Wizard. I highly recommend that anyone running Windows 2003 upgrade to SP1 and run this tool. While you are running this Wizard, it will ask you if you want to remove write priviledges on web folders.  It will also custom build you a Windows firewall based on the application you have installed, I DO NOT recommend this firewall be your only line of defense between you and the internet, but the more layers between you and the bad guys the better.   W2K3 SP1 also improves and hardens IIS 6.  So, if you run your own site and have the ability to upgrade to W2K3 SP1 and Run the Security Configuration Wizard, do so ASAP**. WWF still works perfectly after you harden your servers. You will, however, need to go back and add write permissions to the 'uploads' once you complete the wizard if you allow Image and Avatar uploads from your site, but only on the 'Uploads' folder.

This will by no means make your server unhackable, but it adds another layer of complexity for anyone trying to mess it up.

 **As always, read up on the Security Configuration Wizard before winging the upgrade.  MS has tons of articles on this... Google it and make sure you know a little more about it before hand. Never hurts.

Later,
Back to Top
rbird View Drop Down
Newbie
Newbie


Joined: 06 August 2005
Status: Offline
Points: 3
Post Options Post Options   Thanks (0) Thanks(0)   Quote rbird Quote  Post ReplyReply Direct Link To This Post Posted: 06 August 2005 at 11:04am

We've placed the new updates and moved the database and all is fine but no one can post now!  Any clues?  Registration works fine so the the db is writable.  http://www.daisymuseum.com/forum

Back to Top
ToJaRo View Drop Down
Groupie
Groupie
Avatar

Joined: 20 April 2005
Location: United States
Status: Offline
Points: 158
Post Options Post Options   Thanks (0) Thanks(0)   Quote ToJaRo Quote  Post ReplyReply Direct Link To This Post Posted: 06 August 2005 at 12:12pm
Your site says version 7.01... did you upgrade to the 7.9 files before applying the 7.92 files?  It looks to me as if all the files have not been updated.  Just a thought, I could be wrong.  Also... make sure you post your errors so we can see them... I took the liberty for you:

Microsoft VBScript runtime error '800a01f4'

Variable is undefined: 'removeLongText'

/forum/post_message.asp, line 298


Back to Top
 Post Reply Post Reply Page  <1234>

Forum Jump Forum Permissions View Drop Down

Forum Software by Web Wiz Forums® version 12.08
Copyright ©2001-2026 Web Wiz Ltd.


Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, € prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz Ltd. All rights reserved.